VDB
CVE-2021-31866
CVE-2021-31866
PUBLISHED
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
EPSS 0.44% · 63.7th percentile
Risk Scores
EPSS Score
0.44%
63.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | redmine | 0, 4.1.0 |
| Bitnami | redmine | 0, 4.1.0 |
Exploit Intelligence
Timeline
- Apr 28, 2021 EPSS Score
- Apr 28, 2021 CVE Published
- Jul 1, 2021 EPSS Score
- Sep 1, 2021 EPSS Score
- Nov 3, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 7, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 8, 2022 EPSS Score
- Jul 10, 2022 EPSS Score
- Sep 11, 2022 EPSS Score